VARIoT IoT vulnerabilities database
| VAR-202604-4026 | CVE-2026-5363 | TP-LINK Technologies of Archer C7 Cryptographic Strength Vulnerability in Firmware |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using RSA-1024 before sending it to the router during login.
An adjacent attacker with the ability to intercept network traffic could potentially perform a brute-force or factorization attack against the 1024-bit RSA key to recover the plaintext administrator password, leading to unauthorized access and compromise of the device configuration. This issue affects Archer C7: through Build 20220715. RSA-1024 It is encrypted using and sent to the router. Archer C7 of 2022 Year 7 Moon 15 This will affect the daily build.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-2629 | CVE-2026-39813 | fortinet's FortiSandbox Past traversal vulnerability in |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here>. Fortinet FortiSandbox version of 5.0.0 from 5.0.5 ,and 4.4.0 from 4.4.8 in '../filedir' A path traversal vulnerability exists. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-3550 | CVE-2026-39812 | fortinet's FortiSandbox Cross-site scripting vulnerabilities in multiple products, including |
CVSS V2: - CVSS V3: 4.8 Severity: MEDIUM |
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandbox PaaS 4.2 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>. This vulnerability allows an attacker to... insert attack vector here It may be possible to execute malicious code or commands through this.Some of the information handled by the software may be leaked to the outside. Also, some of the information handled by the software may be rewritten. Furthermore, the software will not stop. Furthermore, attacks exploiting this vulnerability may affect other software
| VAR-202604-3993 | CVE-2026-39808 | fortinet's FortiSandbox In OS Command injection vulnerability |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-3329 | CVE-2026-27316 | fortinet's FortiSandbox Vulnerabilities related to insufficient protection of authentication information in multiple products, including |
CVSS V2: - CVSS V3: 2.7 Severity: LOW |
A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side inspection. This vulnerability allows authenticated administrators to perform client-side checks. LDAP It is possible to read the server's authentication information.There is a possibility that some of the information handled by the software may be leaked to the outside. However, the information handled by the software will not be rewritten. Furthermore, the software will not stop. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-3534 | CVE-2026-25691 | fortinet's FortiSandbox Path traversal vulnerabilities in multiple products, including |
CVSS V2: - CVSS V3: 6.7 Severity: MEDIUM |
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests. In addition, all of the information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-2837 | CVE-2025-61886 | fortinet's FortiSandbox Cross-site scripting vulnerabilities in multiple products, including |
CVSS V2: - CVSS V3: 5.4 Severity: MEDIUM |
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox PaaS 5.0.0 through 5.0.4 may allow an attacker to perform an XSS attack via crafted HTTP requests. [CWE-79] There is a vulnerability that allows an attacker to craft a specially made attack. HTTP via request XSS It may be possible to carry out the attack.Some of the information handled by the software may be leaked to the outside. Also, some of the information handled by the software may be rewritten. Furthermore, the software will not stop. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-4209 | CVE-2024-23104 | fortinet's FortiNDR Information leakage vulnerabilities in multiple products, including |
CVSS V2: - CVSS V3: 5.4 Severity: MEDIUM |
An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiVoice 7.0.0 through 7.0.1 may allow a remote authenticated attacker with at least read-only permission on system maintenance to access backup information via crafted HTTP requests. During system maintenance, a remotely authenticated attacker with at least read-only privileges could potentially access it. HTTP It may be possible to access backup information via a request.There is a possibility that some of the information handled by the software may be leaked to the outside. However, the information handled by the software will not be rewritten. Furthermore, the software will not stop. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-1847 | CVE-2026-31924 | Apache Software Foundation of APISIX Vulnerability in plaintext transmission of important information in |
CVSS V2: - CVSS V3: 5.3 Severity: MEDIUM |
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX.
tencent-cloud-cls log export uses plaintext HTTP
This issue affects Apache APISIX: from 2.99.0 through 3.15.0.
Users are recommended to upgrade to version 3.16.0, which fixes the issue. 3.16.0 It is recommended to upgrade to .There is a possibility that some of the information handled by the software may be leaked to the outside. However, the information handled by the software will not be rewritten. Furthermore, the software will not stop. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-1987 | CVE-2026-31923 | Apache Software Foundation of APISIX Vulnerability in plaintext transmission of important information in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX.
This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default.
This issue affects Apache APISIX: from 0.7 through 3.15.0.
Users are recommended to upgrade to version 3.16.0, which fixes the issue. 3.16.0 It is recommended to upgrade to .All information handled by the software may be leaked to the outside. In addition, information handled by the software will not be rewritten. Furthermore, the software will not stop. Furthermore, attacks exploiting this vulnerability will not affect other software
| VAR-202604-1913 | CVE-2026-31908 | Apache Software Foundation of APISIX Vulnerability in sanitizing special elements in |
CVSS V2: - CVSS V3: 9.1 Severity: CRITICAL |
Header injection vulnerability in Apache APISIX.
The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers.
This issue affects Apache APISIX: from 2.12.0 through 3.15.0.
Users are recommended to upgrade to version 3.16.0, which fixes the issue. 3.16.0 It is recommended to upgrade to .All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software will not stop. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-1914 | CVE-2025-40745 | Siemens' Simcenter 3d Vulnerabilities related to certificate validation in multiple products, including |
CVSS V2: - CVSS V3: 3.7 Severity: Medium |
A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Tecnomatix Plant Simulation (All versions < V2504.0008). Affected applications do not properly validate client certificates to connect to Analytics Service endpoint. This could allow an unauthenticated remote attacker to perform man in the middle attacks. Man-in-the-Middle They may carry out an attack.- Some of the information handled by the software may be leaked to external parties. - No rewriting will occur to the information handled by the software. - The software will not stop
| VAR-202604-2239 | CVE-2026-6024 | Shenzhen Tenda Technology Co.,Ltd. of i6 Path traversal vulnerability in firmware |
CVSS V2: 7.5 CVSS V3: 7.3 Severity: Medium |
A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-2498 | CVE-2026-6016 | Shenzhen Tenda Technology Co.,Ltd. of AC9 Multiple vulnerabilities in firmware |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: High |
A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of the argument WANS results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The attack code is publicly available and could be exploited.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-3433 | CVE-2026-6015 | Shenzhen Tenda Technology Co.,Ltd. of AC9 Multiple vulnerabilities in firmware |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: High |
A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. An exploit is publicly available and can be exploited in the wild.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-1660 | CVE-2026-35063 | OpenPLC Project of OpenPLC_v3 Lack of Authentication Vulnerability in Firmware |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other user, including administrators, by specifying their user ID or they can create new accounts with role=admin, escalating to full administrator access. role=admin You can create a new account to gain full administrator access.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-1661 | CVE-2026-35556 | OpenPLC Project of OpenPLC_v3 Vulnerability regarding plaintext storage of authentication information in firmware |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive information. In addition, information handled by the software will not be rewritten. Furthermore, the software will not stop. Furthermore, attacks exploiting this vulnerability will not affect other software
| VAR-202604-1659 | CVE-2026-28205 | OpenPLC Project of OpenPLC_v3 Vulnerability in firmware where resources are initialized to insecure default values |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypassing authentication via an API. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-2496 | CVE-2026-5962 | Shenzhen Tenda Technology Co.,Ltd. of ch22 Path traversal vulnerability in firmware |
CVSS V2: 7.5 CVSS V3: 7.3 Severity: Medium |
A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction of the component httpd. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used. The exploit has already been exposed and is at risk of being misused.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software
| VAR-202604-3227 | CVE-2026-5849 | Shenzhen Tenda Technology Co.,Ltd. of I12 Path traversal vulnerability in firmware |
CVSS V2: 7.5 CVSS V3: 7.3 Severity: Medium |
A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This exploit is public and could be exploited.All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software may stop working completely. Furthermore, attacks that exploit this vulnerability will not affect other software